π― certification ready Hands-on labs + knowledge assessment
π lab-based examβUnderstanding the invisible waves that connect us β and how they can be protected.β
Welcome to the first module of the Certified Aircrack-ng User course! Aircrack-ng is a powerful tool that helps us understand and test the security of Wi-Fi networks. But before we can use it, we need to understand how Wi-Fi works.
Think of Wi-Fi like a radio station. Just as a radio station broadcasts music through the air, your Wi-Fi router broadcasts data through the air. Anyone with the right receiver can "listen" to that data. That's why security is so important!
In this module, we will learn about the basics of wireless networks β how they work, how they communicate, and what makes them vulnerable. We'll explore the 802.11 family of standards, learn about frames and frequencies, and understand the different ways Wi-Fi networks can be set up.
By the end of this module, you'll have a solid foundation for understanding Wi-Fi security and the tools we'll use to test it.
Let's dive into the invisible world of Wi-Fi! π
By the end of this module, you will be able to:
In a small village in Oyo State, Nigeria, there was a community radio station. Every morning, the announcer would broadcast news, music, and announcements to the whole village.
The radio station used a transmitter to send signals through the air. Villagers had receivers (radios) that could pick up the signal if they tuned to the right frequency.
One day, a group of children discovered that they could also listen to the radio if they had a simple radio. They heard all the announcements. This was okay because the radio station was meant for everyone.
But then, a mischievous boy named Chidi realised that anyone with a radio could listen. He started tuning into the station and making jokes during the news. The station manager was upset. She realised she needed a way to control who could listen and who could broadcast.
This is exactly like Wi-Fi! Wi-Fi signals travel through the air, and anyone with the right equipment can "listen" to them. That's why we need security β to protect the information we send and receive.
Definition: Wi-Fi is a technology that allows devices to connect to the internet or communicate with each other without using cables. It uses radio waves to send and receive data.
Why it matters: Wi-Fi is everywhere β in homes, schools, cafes, and offices. Understanding how it works is the first step to securing it.
Simple explanation: Wi-Fi is like a walkie-talkie, but much faster and smarter. It lets your phone, laptop, or tablet talk to a router without any wires.
+-----------------------------------+ | Wi-Fi = WIRELESS INTERNET | | (No cables, just radio waves) | +-----------------------------------+
π Mini summary: Wi-Fi uses radio waves to connect devices without wires.
Definition: 802.11 is the family of standards that defines how Wi-Fi networks should work. It's like a rulebook that ensures all Wi-Fi devices can talk to each other.
Why it matters: Without standards, different devices might not understand each other. 802.11 makes sure everything works together.
School example: It's like having a common language in a classroom. Everyone uses the same language to communicate. 802.11 is the "language" of Wi-Fi.
| Standard | Speed | Frequency |
|---|---|---|
| 802.11a | 54 Mbps | 5 GHz |
| 802.11b | 11 Mbps | 2.4 GHz |
| 802.11g | 54 Mbps | 2.4 GHz |
| 802.11n | 600 Mbps | 2.4/5 GHz |
| 802.11ac | 1.3 Gbps | 5 GHz |
| 802.11ax (Wi-Fi 6) | 9.6 Gbps | 2.4/5/6 GHz |
π Mini summary: 802.11 standards ensure all Wi-Fi devices work together.
Definition: Frequency bands are the range of radio waves that Wi-Fi uses to transmit data.
Why it matters: Different bands have different strengths and weaknesses.
| Band | Pros | Cons |
|---|---|---|
| 2.4 GHz | Travels farther, better through walls | More crowded, slower |
| 5 GHz | Faster, less crowded | Doesn't travel as far |
Fun example: 2.4 GHz is like a deep voice that can be heard far away. 5 GHz is like a high-pitched voice that is clearer but doesn't travel as far.
π Mini summary: 2.4 GHz goes farther but is slower; 5 GHz is faster but shorter range.
Definition: Channels are like lanes on a highway β they divide the frequency band so multiple devices can use it without interfering.
Why it matters: If too many devices use the same channel, the network becomes slow and unreliable.
Home example: Imagine your Wi-Fi router is like a radio station. Channels are like different frequencies on the radio dial.
CHANNELS (2.4 GHz): 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13 RECOMMENDED: 1, 6, 11 (they don't overlap)
π Mini summary: Channels divide the frequency band to reduce interference.
Definition: SSID (Service Set Identifier) is the name of your Wi-Fi network. BSSID (Basic Service Set Identifier) is the MAC address of the access point.
Why it matters: You need to know the SSID to connect to a network. The BSSID helps identify the specific router.
Simple explanation: SSID is like the name of a shop. BSSID is like the shop's unique address.
SSID: "HomeWiFi" BSSID: 00:11:22:33:44:55
π Mini summary: SSID is the network name; BSSID is the MAC address of the router.
Definition: Infrastructure mode uses an access point (router) to connect devices. Ad-hoc mode allows devices to connect directly to each other.
Why it matters: Most home and office networks use infrastructure mode. Ad-hoc is used for temporary connections.
Nigerian example: In a small cybercafe in Lagos, the computers connect to a central router (infrastructure). Two friends sharing files directly with each other is ad-hoc.
INFRASTRUCTURE: Device β Access Point β Device AD-HOC: Device β Device (direct)
π Mini summary: Infrastructure uses a router; ad-hoc connects devices directly.
Definition: Frames are the basic units of data sent over a Wi-Fi network. They are like envelopes carrying information.
Why it matters: Everything sent over Wi-Fi β websites, messages, emails β is broken down into frames.
School example: It's like sending a letter. The frame is the envelope, and the data is the letter inside.
FRAME STRUCTURE: [Header] [Data] [Trailer] - Header: Where the frame is going - Data: The actual information - Trailer: Checksum for errors
π Mini summary: Frames are the building blocks of Wi-Fi communication.
Definition: Beacon frames are broadcast signals that access points send out to announce their presence.
Why it matters: Beacon frames are how your device finds available Wi-Fi networks.
Fun example: It's like a lighthouse sending out a light signal. "I'm here! Come connect!"
BEACON FRAME CONTAINS: - SSID (network name) - BSSID (MAC address) - Supported speeds - Security settings (WEP, WPA, etc.)
π Mini summary: Beacon frames are announcements from access points.
Definition: Probe requests are signals sent by devices asking "Is there a network with this name?" Probe responses are the access point's reply.
Why it matters: This is how devices find networks they want to connect to.
Home example: When you open your phone's Wi-Fi settings, it sends probe requests to find nearby networks.
DEVICE: "Are you 'HomeWiFi'?" (Probe Request) ROUTER: "Yes, I am 'HomeWiFi'." (Probe Response)
π Mini summary: Probe requests and responses are the "hello" of Wi-Fi.
Definition: Authentication is the process of verifying that a device is allowed to connect. Association is the process of establishing the connection.
Why it matters: This is where security checks happen.
STEP 1: Device discovers network (beacon/probe) STEP 2: Authentication (password check) STEP 3: Association (connection established)
π Mini summary: Authentication verifies, association connects.
Definition: Security types are the methods used to protect Wi-Fi communications.
| Type | Description | Security Level |
|---|---|---|
| Open | No security β anyone can connect | None |
| WEP | Older, weak security | Very low |
| WPA | Better security | Medium |
| WPA2 | Strong security (most common) | High |
| WPA3 | Newest, strongest | Very high |
π Mini summary: WPA2 and WPA3 are the most secure types.
Definition: Wi-Fi signals travel through the air, so anyone within range can pick them up. This is called the "open air" problem.
Why it matters: Attackers can "listen in" on Wi-Fi communications if they are not properly secured.
Simple explanation: It's like having a conversation in a crowded room. Anyone nearby can hear what you say if you're not whispering.
π Mini summary: Wi-Fi signals are public β they need protection.
Definition: Aircrack-ng is a suite of tools for testing and assessing Wi-Fi security. It includes tools for capturing packets, cracking passwords, and analysing networks.
Why it matters: This is the tool we'll be learning to use throughout this course.
KEY TOOLS IN AIRCRACK-NG: - airmon-ng: Enables monitor mode - airodump-ng: Captures packets - aireplay-ng: Injects packets - aircrack-ng: Cracks passwords
π Mini summary: Aircrack-ng is a toolkit for Wi-Fi security testing.
Definition: Using Aircrack-ng and similar tools without permission is illegal. You should only test networks you own or have explicit permission to test.
Why it matters: Ethical use ensures we improve security, not break the law.
Nigerian example: In Nigeria, unauthorised access to networks is a cybercrime under the Cybercrime (Prohibition, Prevention, etc.) Act. Always get written permission before testing.
π Mini summary: Always use these tools ethically and legally.
Here is the journey a wireless packet takes:
APPLICATION β ENCAPSULATED β FRAME β OVER THE AIR β DECODED β APPLICATION
Each step is an opportunity for security checks and vulnerabilities.
π Mini summary: Wi-Fi communication is a journey from one device to another through the air.
DISCOVER β PROBE β AUTHENTICATE β ASSOCIATE β DATA
Tip: Use the village radio station story to introduce the concept of open-air broadcasting. Encourage students to think of other examples of invisible communication (like radio, TV, Bluetooth).
The 2.4 GHz band is also used by other devices like Bluetooth, microwave ovens, and baby monitors. This is why Wi-Fi can sometimes be slow β it's sharing the airwaves!
DEVICE ACCESS POINT
| |
| --- BEACON FRAME ---> |
| |
| --- PROBE REQUEST ---> |
| <--- PROBE RESPONSE --- |
| |
| --- AUTHENTICATION ---> |
| <--- SUCCESS --- |
| |
| --- ASSOCIATION ---> |
| <--- SUCCESS --- |
| |
| ===== DATA =====> |
| Band | Range | Speed | Interference |
|---|---|---|---|
| 2.4 GHz | Long | Slow | High (crowded) |
| 5 GHz | Short | Fast | Low |
WEP (1997) β WPA (2003) β WPA2 (2004) β WPA3 (2018) Weak Strong Strongest
We included mini summaries after each lesson. Let's now wrap up the entire module.
In this module, we built a strong foundation in Wi-Fi fundamentals. We learned that Wi-Fi is a wireless technology that uses radio waves to transmit data. We explored the 802.11 family of standards, which ensure all Wi-Fi devices can communicate with each other.
We covered the differences between the 2.4 GHz and 5 GHz frequency bands, and the concept of channels that divide these bands. We learned about SSID (network name) and BSSID (MAC address), and the differences between infrastructure and ad-hoc networks.
We also delved into the structure of Wi-Fi frames, the role of beacon frames, and the process of probe requests and responses. We learned about authentication and association, and the various security types from WEP to WPA3.
Finally, we introduced the Aircrack-ng suite and emphasised the importance of legal and ethical use. This module provides the essential knowledge needed to understand and work with Wi-Fi networks.
Match the term with its description:
| Term | Description |
|---|---|
| 1. SSID | A. MAC address of access point |
| 2. BSSID | B. Network name |
| 3. Beacon | C. Network announcement |
| 4. Probe | D. Query for a network |
| 5. WPA2 | E. Strong Wi-Fi security |
Answers: 1-B, 2-A, 3-C, 4-D, 5-E
Scenario: You are setting up a new Wi-Fi network for your home. You want it to be fast and secure.
In groups, draw a diagram showing the process of a device connecting to a Wi-Fi network. Include: beacon, probe, authentication, association, and data transfer. Present your diagram to the class.
Look at the Wi-Fi networks available on your phone or computer. Note down the SSIDs you see. Can you identify the security type? Write a short report on what you found.
Create a poster explaining the basics of Wi-Fi. Include: what Wi-Fi is, frequency bands, security types, and a diagram of the connection process. Make it colourful and easy to understand.
Using your phone or laptop, scan for Wi-Fi networks in your area. Note down the SSIDs, BSSIDs, channels, and security types you see. Write a report summarising your findings.
Research and write a brief report on the history of Wi-Fi. Include: the first standard, how it evolved, and the latest developments (like Wi-Fi 6).
In Module 2, we will dive into the Aircrack-ng suite itself. We'll learn how to install it, enable monitor mode, and start capturing packets. Make sure you understand the basics from this module β they will be essential.
Get ready to get hands-on with the tools!
See you in Module 2!
π‘ End of Module 1 β Wi-Fi Fundamentals and 802.11 Basics π
βMeet your toolkit β the Swiss Army knife of Wi-Fi security testing.β
In Module 1, we learned the basics of Wi-Fi β how it works, how it communicates, and why security is important. Now it's time to meet the tools that will help us test and understand Wi-Fi security: the Aircrack-ng suite.
The Aircrack-ng suite is like a toolbox for wireless security. It contains many different tools, each designed for a specific job. Some tools capture packets, some inject packets, and some crack passwords. Together, they give us everything we need to assess the security of a Wi-Fi network.
In this module, we will explore each tool in the suite, learn what it does, and understand when to use it. We'll also set up our environment and get ready to use these tools in the upcoming modules.
Let's open the toolbox! π§
By the end of this module, you will be able to:
In a workshop in Enugu, Nigeria, there was a master carpenter named Mr. Eze. He had a large wooden toolbox. Inside were many tools β hammers, saws, chisels, planes, and screwdrivers.
Each tool had a specific job:
Mr. Eze knew exactly which tool to use for each job. He never used a hammer to cut wood, or a saw to drive nails. He understood his tools.
The Aircrack-ng suite is like Mr. Eze's toolbox. Each tool has a specific purpose. Knowing which tool to use and when is the key to mastering Wi-Fi security testing.
Definition: Aircrack-ng is a suite of tools designed for assessing Wi-Fi network security. It can capture packets, inject packets, and crack passwords.
Why it matters: It's the most popular and widely used toolkit for Wi-Fi security testing.
Simple explanation: It's like a Swiss Army knife β it has many different tools in one package.
+-----------------------------------+ | AIRCRACK-NG = WI-FI TOOLKIT | | (Capture, Inject, Crack) | +-----------------------------------+
π Mini summary: Aircrack-ng is a complete toolkit for Wi-Fi security testing.
The Aircrack-ng suite contains many tools. Here are the most important ones:
| Tool | Purpose |
|---|---|
| airmon-ng | Enables monitor mode on wireless interfaces |
| airodump-ng | Captures and displays Wi-Fi packets |
| aireplay-ng | Injects packets (sends crafted packets) |
| aircrack-ng | Cracks WEP and WPA/WPA2 passwords |
| airdecap-ng | Decrypts captured packets |
| airolib-ng | Manages databases for password cracking |
| airbase-ng | Creates fake access points |
π Mini summary: Each tool has a specific purpose β together they cover all aspects of Wi-Fi security testing.
Definition: airmon-ng is the tool that enables monitor mode on your wireless adapter.
Why it matters: Without monitor mode, your adapter can only connect to networks (managed mode). Monitor mode allows you to capture all Wi-Fi traffic, not just your own.
School example: Managed mode is like being a student who only listens to the teacher. Monitor mode is like being the principal who can listen to everything happening in the school.
COMMAND TO START MONITOR MODE: airmon-ng start wlan0
π Mini summary: airmon-ng switches your adapter to monitor mode.
Definition: airodump-ng is the tool that captures Wi-Fi packets and displays them in real time.
Why it matters: This is how you see what's happening on the network β the SSIDs, BSSIDs, channels, and clients.
Fun example: It's like a fisherman casting a net into the water and seeing all the fish swimming by. airodump-ng captures all the Wi-Fi "fish" (packets).
COMMAND TO CAPTURE PACKETS: airodump-ng wlan0mon
π Mini summary: airodump-ng captures and displays Wi-Fi traffic.
Definition: aireplay-ng is the tool that injects (sends) crafted packets into a Wi-Fi network.
Why it matters: Injection is used to speed up captures, deauthenticate clients, and perform various attacks.
Home example: It's like being able to talk to people in a room and get them to respond. aireplay-ng sends special messages to devices on a Wi-Fi network.
COMMAND TO DEAUTHENTICATE A CLIENT: aireplay-ng -0 1 -a [BSSID] -c [Client MAC] wlan0mon
π Mini summary: aireplay-ng sends crafted packets into a network.
Definition: aircrack-ng is the tool that cracks WEP and WPA/WPA2 passwords using captured packets.
Why it matters: This is the tool that actually finds the password. It's the namesake of the entire suite.
Simple explanation: It's like having a puzzle solver that tries many combinations until it finds the right one.
COMMAND TO CRACK WPA HANDSHAKE: aircrack-ng -w dictionary.txt capture.cap
π Mini summary: aircrack-ng cracks Wi-Fi passwords.
Definition: airdecap-ng is the tool that decrypts captured packets when you have the password.
Why it matters: Once you know the password, you can decrypt captured traffic to see what was being sent.
COMMAND TO DECRYPT CAPTURE: airdecap-ng -p password capture.cap
π Mini summary: airdecap-ng decrypts captured packets.
Definition: airolib-ng is a tool that manages databases of passwords for faster cracking.
Why it matters: It speeds up the cracking process by using precomputed data.
COMMAND TO CREATE A DATABASE: airolib-ng database.db --import passwd dictionary.txt
π Mini summary: airolib-ng manages password databases for faster cracking.
Definition: airbase-ng is a tool that creates fake access points (rogue APs).
Why it matters: It's used in attacks like "Evil Twin" where you create a fake network to trick users into connecting.
Nigerian example: In a busy market in Lagos, a fake Wi-Fi network called "Free Market Wi-Fi" might be set up to capture people's information. airbase-ng can create such networks.
COMMAND TO CREATE A FAKE AP: airbase-ng -e "FreeWiFi" -c 6 wlan0mon
π Mini summary: airbase-ng creates fake access points.
Definition: Monitor mode allows a Wi-Fi adapter to capture all packets without connecting to a network. Managed mode is the normal mode where the adapter connects to a network.
Why it matters: Most tools require monitor mode to work.
| Mode | Description |
|---|---|
| Managed | Connects to a network β normal use |
| Monitor | Captures all packets β for testing |
π Mini summary: Monitor mode is for capturing all traffic; managed mode is for connecting.
Here's how to install Aircrack-ng on different operating systems:
sudo apt-get install aircrack-ngsudo yum install aircrack-ngbrew install aircrack-ngπ Mini summary: Installation is easy β just use the package manager for your OS.
Definition: Packet injection is the ability to send crafted packets into a network. Not all adapters support it.
Why it matters: Injection is essential for many attacks, like deauthentication and ARP replay.
COMMAND TO TEST INJECTION: aireplay-ng --test wlan0mon
π Mini summary: Test your adapter's injection capability before using it.
Not all Wi-Fi adapters work with Aircrack-ng. Look for:
Simple explanation: It's like choosing a car that can go off-road β not all cars can do it.
π Mini summary: Choose an adapter that supports monitor mode and injection.
Here is a typical workflow for WPA cracking:
1. airmon-ng start wlan0 β Enable monitor mode
2. airodump-ng wlan0mon β Find target network
3. airodump-ng -c 6 --bssid XX:XX:XX:XX:XX:XX -w capture wlan0mon
β Capture handshake
4. aireplay-ng -0 2 -a XX:XX:XX:XX:XX:XX -c [client] wlan0mon
β Deauthenticate client to force handshake
5. aircrack-ng -w dictionary.txt capture.cap
β Crack the password
π Mini summary: The tools work together in a specific sequence.
Definition: These tools are for authorised testing only. Using them without permission is illegal.
Why it matters: Being ethical ensures we improve security, not break the law.
Nigerian example: Under the Cybercrime (Prohibition, Prevention, etc.) Act 2015, unauthorised access to networks is a crime. Always get written permission.
π Mini summary: Only use these tools on networks you own or have permission to test.
iwconfig or ifconfig.airmon-ng start wlan0iwconfig should show "Mode:Monitor".aireplay-ng --test wlan0monairodump-ng wlan0monINSTALL β CONNECT β IDENTIFY β MONITOR β VERIFY β TEST β CAPTURE
Tip: Use the carpenter's toolbox story to explain the different tools. Have students identify which tool they would use for different tasks.
The Aircrack-ng suite can also be used on Android devices using tools like bcmon or Nethunter!
iwconfig.
airmon-ng β airodump-ng β aireplay-ng β aircrack-ng
(enable (capture (inject (crack
monitor) packets) packets) password)
| Tool | Function |
|---|---|
| airmon-ng | Enable monitor mode |
| airodump-ng | Capture packets |
| aireplay-ng | Inject packets |
| aircrack-ng | Crack passwords |
MANAGED: Device connects to a network (normal use) MONITOR: Device captures all packets (testing)
We included mini summaries after each lesson. Let's now wrap up the entire module.
In this module, we explored the Aircrack-ng suite β a comprehensive toolkit for Wi-Fi security testing. We learned about the main tools: airmon-ng (enables monitor mode), airodump-ng (captures packets), aireplay-ng (injects packets), and aircrack-ng (cracks passwords). We also covered other tools like airdecap-ng, airolib-ng, and airbase-ng.
We discussed the importance of monitor mode, the difference between monitor and managed modes, and how to test packet injection. We also covered installation steps, choosing the right wireless adapter, and the typical workflow for a security test.
Remember, these tools are powerful β with great power comes great responsibility. Always use them ethically and legally.
Match the tool with its function:
| Tool | Function |
|---|---|
| 1. airmon-ng | A. Captures packets |
| 2. airodump-ng | B. Enables monitor mode |
| 3. aireplay-ng | C. Cracks passwords |
| 4. aircrack-ng | D. Injects packets |
| 5. airbase-ng | E. Creates fake APs |
Answers: 1-B, 2-A, 3-D, 4-C, 5-E
Scenario: You are a security consultant hired to test the Wi-Fi security of a small business. You have your laptop and a compatible wireless adapter.
In groups, create a poster showing the Aircrack-ng workflow. Include all the main tools, their purposes, and the order in which they are used. Present your poster to the class.
Check your system's wireless adapter. Does it support monitor mode? Does it support packet injection? Write a short report on your findings.
Create a reference card for the Aircrack-ng suite. Include each tool, its purpose, and a sample command. Make it something you could use in a lab.
Install Aircrack-ng on your system. Enable monitor mode on your adapter. Test packet injection. Take screenshots of each step and write a report.
Research and write a report on a real-world Wi-Fi security incident. Explain how Aircrack-ng tools could have been used to detect or prevent the incident.
In Module 3, we will dive deeper into Monitor Mode and Packet Capture. We'll learn how to use airodump-ng effectively, how to filter captures, and how to save and analyse capture files.
Make sure you have Aircrack-ng installed and a compatible adapter ready.
See you in Module 3!
π οΈ End of Module 2 β Aircrack-ng Suite Overview π
βHow to put on your special glasses and see all the Wi-Fi traffic around you.β
In Module 2, we learned about the Aircrack-ng suite and its tools. Now it's time to start using them! The first step in any Wi-Fi security test is to see what's out there. That means putting your wireless adapter into monitor mode and capturing packets.
Think of monitor mode like putting on a pair of special glasses that let you see all the invisible signals around you. Normally, your Wi-Fi adapter only "sees" the network it's connected to. In monitor mode, it sees everything β all the networks, all the devices, all the conversations.
In this module, we will learn how to enable monitor mode, capture packets with airodump-ng, and analyse what we see. We'll also learn how to save captures and use them later.
Let's put on our special glasses! π
By the end of this module, you will be able to:
In a busy market in Lagos, Nigeria, there was a journalist named Ade. Ade wanted to understand the conversations happening in the market β who was selling what, who was buying, and how much things cost.
But instead of asking people directly, Ade had a special recording device that could listen to all the conversations happening in the market. He didn't just listen to one stall β he listened to everything.
He recorded all the voices, then later analysed them. He could hear a woman buying tomatoes, a man selling electronics, and a child asking for sweets.
This is exactly what monitor mode and packet capture do. They let you listen to all the Wi-Fi conversations happening around you. You can see who is talking, what they're saying, and where they're going.
Definition: Monitor mode is a special mode of a Wi-Fi adapter that allows it to capture all wireless traffic, not just traffic addressed to it.
Why it matters: Without monitor mode, your adapter can only see traffic to and from your own device. With monitor mode, you can see everything in range.
Simple explanation: Managed mode is like a student listening only to their teacher. Monitor mode is like a principal listening to every conversation in the school.
MANAGED MODE: Sees only your own traffic MONITOR MODE: Sees all traffic in range
π Mini summary: Monitor mode lets your adapter see all Wi-Fi traffic, not just your own.
Definition: airmon-ng is the tool that enables monitor mode on your wireless adapter.
Why it matters: This is the first step in any Wi-Fi security test.
School example: It's like turning on a special setting on your phone to see all the Wi-Fi networks around you.
COMMAND TO START MONITOR MODE: sudo airmon-ng start wlan0 OUTPUT: (interface wlan0mon)
π Mini summary: airmon-ng starts monitor mode on your adapter.
Definition: Your wireless interface is the name of your Wi-Fi adapter (like wlan0, wlp2s0, etc.).
Why it matters: You need to know the interface name to use the tools.
Home example: It's like knowing your phone's name so you can connect it to a computer.
COMMAND TO LIST INTERFACES: iwconfig or ifconfig
π Mini summary: Use iwconfig or ifconfig to find your interface name.
Definition: airodump-ng is the tool that captures Wi-Fi packets and displays them in real time.
Why it matters: This is how you see what's happening on the network β the SSIDs, BSSIDs, channels, and clients.
Fun example: It's like a fisherman casting a net into the water and seeing all the fish swimming by. airodump-ng captures all the Wi-Fi "fish" (packets).
COMMAND TO CAPTURE PACKETS: sudo airodump-ng wlan0mon
π Mini summary: airodump-ng captures and displays Wi-Fi traffic.
When you run airodump-ng, you'll see a screen with several sections:
BSSID PWR Beacons #Data CH ENC ESSID XX:XX:XX:XX:XX:XX -60 10 100 6 WPA2 HomeWiFi
π Mini summary: airodump-ng shows you all the networks and clients in range.
Definition: The client list shows the devices connected to each access point.
Why it matters: This tells you who is using the network.
BSSID STATION PWR XX:XX:XX:XX:XX:XX YY:YY:YY:YY:YY:YY -65 (access point) (client)
π Mini summary: The client list shows which devices are connected to each network.
Definition: You can tell airodump-ng to focus on a specific channel to capture more data from that network.
Why it matters: It improves capture efficiency and reduces noise.
COMMAND: sudo airodump-ng -c 6 wlan0mon (captures only channel 6)
π Mini summary: Use -c to focus on a specific channel.
Definition: You can filter to capture packets from a specific access point only.
Why it matters: This lets you focus on one network and ignore others.
COMMAND: sudo airodump-ng --bssid XX:XX:XX:XX:XX:XX -c 6 wlan0mon
π Mini summary: Use --bssid to focus on one access point.
Definition: You can save captured packets to a file for later analysis.
Why it matters: You can't always analyse everything live. Saving allows you to review later.
COMMAND: sudo airodump-ng -w capture wlan0mon (saves to capture-01.cap, capture-02.cap, etc.)
π Mini summary: Use -w to save captures to a file.
Aircrack-ng saves captures in .cap format. This is a standard format used by many Wi-Fi tools.
FILE: capture-01.cap (can be opened with Wireshark, aircrack-ng, etc.)
π Mini summary: .cap files store captured packets for later use.
Definition: Wi-Fi frames come in three types:
Simple explanation: Data frames are like letters. Control frames are like "I got your letter" replies. Management frames are like invitations.
π Mini summary: Wi-Fi frames are classified into data, control, and management frames.
Definition: The 4-way handshake is the exchange of frames when a device connects to a WPA/WPA2 network.
Why it matters: Capturing the handshake is essential for cracking WPA/WPA2 passwords.
Handshake frames: EAPOL (1, 2, 3, 4)
π Mini summary: The 4-way handshake is key to WPA cracking.
Definition: When you're done, you should disable monitor mode to return your adapter to normal operation.
COMMAND: sudo airmon-ng stop wlan0mon (or simply: sudo airmon-ng stop wlan0)
π Mini summary: Always stop monitor mode when you're finished.
If monitor mode isn't working:
sudo (administrator privileges).π Mini summary: Common issues include driver problems, wrong interface name, or lack of support.
Here is the complete capture workflow:
1. sudo airmon-ng start wlan0 β Enable monitor mode
2. sudo airodump-ng wlan0mon β Find target network
3. sudo airodump-ng -c 6 --bssid XX:XX:XX:XX:XX:XX -w capture wlan0mon
β Capture on target
4. (Wait for handshake or data)
5. Ctrl+C to stop capture
6. Examine capture file
π Mini summary: The workflow: enable monitor mode, scan, focus on target, capture, stop, analyse.
sudo airmon-ng start wlan0sudo airodump-ng wlan0monsudo airodump-ng -c 6 --bssid XX:XX:XX:XX:XX:XX -w capture wlan0monMONITOR β SCAN β TARGET β FOCUS β WAIT β STOP β VERIFY
Tip: Have students practice in a lab environment. Use a simple network (like a home router) for hands-on experience. Emphasise the importance of focusing captures on a single channel and BSSID for better results.
Some wireless adapters can only work in managed mode. Always check your adapter's capabilities before starting a security test.
airmon-ng to enable monitor mode.airodump-ng to capture and display packets.-w for later analysis.sudo β monitor mode requires administrator privileges.iwconfig.-c to focus on a specific channel.--bssid to focus on a specific network.+-------------------+-------------------+ | MANAGED MODE | MONITOR MODE | +-------------------+-------------------+ | Connects to AP | Captures all | | Sees own traffic | Sees all traffic | | Normal use | Security testing | +-------------------+-------------------+
BSSID PWR Beacons #Data CH ENC ESSID XX:XX:XX:XX:XX:XX -60 10 100 6 WPA2 HomeWiFi ^^^^^^ ^^^ ^^^^^^^ ^^^^^ ^^ ^^^ ^^^^^^^ MAC Address Signal Beacons Data Channel Security Name
+-------------------+
| airmon-ng start | β Enable monitor mode
+-------------------+
|
+-------------------+
| airodump-ng scan | β Find target network
+-------------------+
|
+-------------------+
| airodump-ng -c | β Focus on target (channel + BSSID)
+-------------------+
|
+-------------------+
| Wait & Capture | β Wait for handshake
+-------------------+
|
+-------------------+
| Ctrl+C to stop | β Save capture file
+-------------------+
We included mini summaries after each lesson. Let's now wrap up the entire module.
In this module, we learned how to put our wireless adapter into monitor mode and capture Wi-Fi packets. We explored the airodump-ng tool, understanding its display and how to filter by channel and BSSID. We also learned how to save captures to files and the importance of capturing the 4-way handshake for WPA cracking.
Monitor mode is the foundation of Wi-Fi security testing. With this skill, you can now see all the networks and devices in your area, and capture the data needed for analysis. In the next module, we'll use this captured data to crack WEP and WPA/WPA2 passwords.
airmon-ng start wlan0.-c followed by the channel number.--bssid.Match the term with its description:
| Term | Description |
|---|---|
| 1. Monitor mode | A. MAC address of access point |
| 2. BSSID | B. Network name |
| 3. ESSID | C. Captures all traffic |
| 4. Handshake | D. WPA/WPA2 connection exchange |
| 5. .cap file | E. Capture file format |
Answers: 1-C, 2-A, 3-B, 4-D, 5-E
Scenario: You are testing your home Wi-Fi network. You want to capture the handshake for later analysis.
In groups, practice the capture workflow. Each group will: enable monitor mode, scan for networks, choose a target, capture packets, and save a .cap file. Discuss any challenges you faced.
Run a scan with airodump-ng and write down the BSSID, channel, and encryption of 5 networks you see. Save a capture file from one network.
Create a reference card for capturing Wi-Fi packets. Include: how to enable monitor mode, how to capture, how to filter, and how to save. Make it something you can use in a lab.
Set up your own Wi-Fi network (or use a lab network). Capture a handshake from this network. Submit the capture file and a report explaining the steps you took.
Capture traffic from a network that is not your own (with permission). Identify the devices connected to it. Write a report on what you found.
airmon-ng to enable monitor mode.airodump-ng to capture and display packets.-w for later analysis.In Module 4, we will use the captured packets to crack WEP passwords. We'll also start exploring WPA/WPA2 cracking techniques.
Make sure you have a good capture file ready to practice with.
See you in Module 4!
π‘ End of Module 3 β Monitor Mode and Packet Capture π
βCracking the old lock that taught us why security matters.β
In Module 3, we learned how to capture packets. Now it's time to use those packets to do something exciting: crack a password. We'll start with WEP β the oldest and weakest Wi-Fi security standard.
Think of WEP like an old, rusty lock. It was designed to keep doors secure, but over time, people found many ways to break it. Today, WEP is considered very weak and should never be used. But learning to crack WEP is a great way to understand how Wi-Fi security works.
In this module, we will learn how WEP works, why it's weak, and how to crack it using Aircrack-ng. We'll use tools like airodump-ng, aireplay-ng, and aircrack-ng to capture enough data and find the password.
Let's crack that old lock! π
By the end of this module, you will be able to:
In a small town in Oyo State, Nigeria, there was an old bank that had been closed for years. In the basement, there was a very old safe. The bank manager said: "This safe is ancient. No one uses it anymore."
But a young security enthusiast named Tunde was curious. He studied the old safe and found that it had a design flaw. The lock mechanism was very simple. With some basic tools, he could figure out the combination in just a few hours.
Tunde opened the safe and found nothing inside β it had been empty for years. But he learned a valuable lesson: old security systems are often vulnerable.
WEP is like that old safe. It was once considered secure, but now we know it's full of flaws. Learning to crack WEP teaches us why we need stronger security like WPA2 and WPA3.
Definition: WEP (Wired Equivalent Privacy) is an older security protocol for Wi-Fi networks. It was designed to provide the same level of security as a wired network.
Why it matters: WEP is weak and easily broken. It was the first Wi-Fi security standard, but it has many flaws.
Simple explanation: WEP is like a lock that looks strong but is actually very easy to pick.
WEP = WIRED EQUIVALENT PRIVACY (Old, weak, easily cracked)
π Mini summary: WEP is an old, weak Wi-Fi security standard.
WEP uses a secret key (the password) to encrypt data. It combines the key with a random number called an Initialisation Vector (IV) to create a new encryption key for each packet.
The problem? The IV is sent in the clear (unencrypted) with each packet. And there are only 16 million possible IVs β which sounds like a lot, but on a busy network, they repeat quickly.
WEP ENCRYPTION: KEY + IV β ENCRYPTED DATA β SENT OVER AIR
π Mini summary: WEP combines a key with an IV, but the IV is sent openly and repeats.
Here are the main reasons WEP is weak:
Fun example: It's like using a lock with only 10 possible combinations. An attacker can try all of them in a few minutes.
π Mini summary: WEP is weak because of small IV space, open IVs, and a weak algorithm.
Definition: An IV (Initialisation Vector) is a random number used to make each packet encrypted differently, even if the key is the same.
Why it matters: WEP sends the IV in the clear. Attackers can collect IVs and use them to crack the key.
School example: It's like a teacher using a different marker for each test. But if the students can see the marker colour, they can predict the answers.
IV = RANDOM NUMBER (SENT IN THE CLEAR)
π Mini summary: The IV is a random number that WEP sends openly β a big weakness.
Definition: The ARP Replay attack is a method to generate many IVs quickly by capturing and replaying ARP packets.
Why it matters: This attack speeds up the IV collection process significantly.
Simple explanation: It's like recording a message and playing it back over and over to see how the system responds.
ARP REPLAY: Capture ARP packet β Replay it β Generate new IVs
π Mini summary: ARP replay creates many IVs quickly to speed up cracking.
Definition: aireplay-ng is the tool that injects packets to generate IVs.
Why it matters: This is the tool we use to perform the ARP replay attack.
COMMAND: aireplay-ng -3 -b [BSSID] wlan0mon (-3 = ARP replay attack)
π Mini summary: aireplay-ng -3 performs the ARP replay attack to generate IVs.
Here is the complete process for cracking WEP:
MONITOR β CAPTURE β INJECT β COLLECT β CRACK
π Mini summary: The process: capture, inject, collect IVs, crack.
Definition: aircrack-ng is the tool that cracks the WEP key from the collected IVs.
Why it matters: This is the final step β it finds the password.
COMMAND: aircrack-ng capture-01.cap
π Mini summary: aircrack-ng finds the WEP key from the captured IVs.
| Key Length | IVs Needed |
|---|---|
| 64-bit (40-bit key) | ~5,000β10,000 |
| 128-bit (104-bit key) | ~15,000β20,000 |
Simple explanation: It's like needing enough pieces of a puzzle to see the full picture. You need enough IVs to crack the key.
π Mini summary: You need 5,000β20,000 IVs depending on the key length.
In a real network, you might see:
aircrack-ng capture-01.cap Opening capture-01.cap Read 10000 packets. Number of IVs: 8000 Trying to crack... KEY FOUND: 12:34:56:78:9A
π Mini summary: aircrack-ng shows the number of IVs and the final key.
Besides ARP replay, there are other WEP attacks:
π Mini summary: There are multiple WEP attacks, but ARP replay is the most common.
WEP was officially deprecated (retired) in 2004. It has been replaced by WPA, WPA2, and WPA3.
Nigerian example: In Nigeria, some older routers still use WEP by default. It's important to upgrade to WPA2 or WPA3 for security.
π Mini summary: WEP is obsolete β always use WPA2 or WPA3.
Definition: You should only crack WEP on networks you own or have explicit permission to test.
Why it matters: Unauthorised access is illegal and unethical.
Simple explanation: It's like having a lock-picking set. Using it on your own door is fine. Using it on someone else's door is a crime.
π Mini summary: Only use WEP cracking on networks you own or have permission to test.
1. sudo airmon-ng start wlan0 β Enable monitor mode
2. sudo airodump-ng wlan0mon β Find target
3. sudo airodump-ng -c 6 --bssid XX:XX:XX:XX:XX:XX -w capture wlan0mon
β Capture on target
4. sudo aireplay-ng -3 -b XX:XX:XX:XX:XX:XX wlan0mon
β ARP replay injection (in another terminal)
5. Wait for ~10,000 IVs
6. sudo aircrack-ng capture-01.cap β Crack the key
π Mini summary: The complete workflow: monitor β capture β inject β collect β crack.
Learning to crack WEP teaches us why we need strong encryption. WPA2 and WPA3 use much stronger algorithms and are not vulnerable to the same attacks.
π Mini summary: Strong encryption (WPA2/WPA3) is essential for modern Wi-Fi security.
sudo airmon-ng start wlan0sudo airodump-ng wlan0monsudo airodump-ng -c [CH] --bssid [BSSID] -w capture wlan0monsudo aireplay-ng -3 -b [BSSID] wlan0monsudo aircrack-ng capture-01.capMONITOR β SCAN β CAPTURE β INJECT β WAIT β STOP β CRACK
Tip: Set up a lab with a WEP-enabled router for hands-on practice. Walk through each step slowly, explaining the purpose of each tool and command.
WEP cracking was one of the first demonstrations of how flawed security standards can put entire networks at risk. This lesson led to the development of WPA and WPA2.
+-------------------+
| airmon-ng start | β Enable monitor mode
+-------------------+
|
+-------------------+
| airodump-ng scan | β Find target
+-------------------+
|
+-------------------+
| airodump-ng -c | β Capture on target
+-------------------+
|
+-------------------+
| aireplay-ng -3 | β ARP replay (inject)
+-------------------+
|
+-------------------+
| Collect IVs | β 5,000β20,000 needed
+-------------------+
|
+-------------------+
| aircrack-ng | β Crack the key
+-------------------+
| Feature | WEP | WPA2 | WPA3 |
|---|---|---|---|
| Security | Very weak | Strong | Strongest |
| Key length | 64/128-bit | 128-bit | 192-bit |
| Status | Obsolete | Current | New |
+-------------------+-------------------+ | Key Length | IVs Needed | +-------------------+-------------------+ | 64-bit (40-bit) | 5,000 - 10,000 | | 128-bit (104-bit)| 15,000 - 20,000 | +-------------------+-------------------+
We included mini summaries after each lesson. Let's now wrap up the entire module.
In this module, we learned about WEP β the first and weakest Wi-Fi security standard. We explored why WEP is flawed (small IV space, open IVs, weak algorithm) and how to crack it using the Aircrack-ng suite. We used airodump-ng to capture traffic, aireplay-ng for ARP replay injection, and aircrack-ng to find the key.
We also discussed the importance of upgrading to WPA2 or WPA3 and the ethical and legal aspects of using these tools. This module serves as a foundation for understanding more advanced attacks in future modules.
Match the term with its description:
| Term | Description |
|---|---|
| 1. WEP | A. Injector tool |
| 2. IV | B. Old, weak Wi-Fi standard |
| 3. ARP replay | C. Cracking tool |
| 4. aireplay-ng | D. Random number |
| 5. aircrack-ng | E. Method to generate IVs |
Answers: 1-B, 2-D, 3-E, 4-A, 5-C
Scenario: You are testing a legacy network that still uses WEP. You need to demonstrate the risk to the management.
In groups, set up a WEP-enabled router in a lab. Practice the full WEP cracking workflow: monitor mode, capture, ARP replay, and cracking. Document each step and share your results with the class.
Research the history of WEP. Write a short report on when it was introduced, why it was created, and why it failed. Include at least three key vulnerabilities.
Create a presentation on WEP security. Include: what it is, why it's weak, how to crack it, and what to use instead. Make it suitable for a non-technical audience.
Set up a WEP network in a lab environment. Capture a WEP handshake and crack the password. Submit your capture file and the cracked key with a report explaining each step.
Research a newer Wi-Fi attack (like PMKID attack). Compare it to WEP cracking. Write a report on the similarities and differences.
In Module 5, we will move on to WPA/WPA2 Handshake Capture and Cracking. This is the most common Wi-Fi security standard today, and the techniques are more advanced.
Make sure you have a good understanding of packet capture before moving on.
See you in Module 5!
π End of Module 4 β WEP Cracking β The Classic Challenge π
βCapturing the secret handshake that unlocks the network.β
In Module 4, we learned how to crack WEP β the oldest and weakest Wi-Fi security. But WEP is outdated. Today, almost all networks use WPA (Wi-Fi Protected Access) or WPA2, which are much stronger.
Think of WPA2 like a modern digital lock with a strong key. It's much harder to break than the old WEP lock. But there is still a way. When a device connects to a WPA/WPA2 network, it goes through a process called the 4-way handshake.
If we can capture that handshake, we can try to crack the password using a dictionary attack β trying many possible passwords until we find the right one.
In this module, we will learn how to capture the 4-way handshake, understand how WPA/WPA2 works, and use aircrack-ng and hashcat to crack the password.
Let's learn the secret handshake! π€
By the end of this module, you will be able to:
In a school in Abuja, Nigeria, there was a secret club. To enter, you had to know the secret handshake. It had four parts:
If you got the handshake right, the door opened. If you got it wrong, you couldn't enter.
One day, a clever student named Chidi watched from a distance. He recorded the handshake with his phone. Then he went home and practised until he got it right.
When he returned to school, he performed the handshake perfectly and was let into the club. Chidi had captured the handshake and learned the secret.
This is exactly what we do with WPA/WPA2. We capture the 4-way handshake (the "secret handshake") between a device and the access point. Then we try many passwords until we find the right one.
Definition: WPA (Wi-Fi Protected Access) and WPA2 are security standards for Wi-Fi networks. They are much stronger than WEP.
Why it matters: WPA2 is the most common Wi-Fi security standard today. Understanding it is essential for modern Wi-Fi security testing.
Simple explanation: WPA2 is like a modern, strong lock. It's much harder to break than the old WEP lock.
WPA = WI-FI PROTECTED ACCESS WPA2 = STRONGER VERSION (Most common standard today)
π Mini summary: WPA2 is the modern, strong Wi-Fi security standard.
WPA/WPA2 uses a shared password (the network key) to encrypt data. The password is not sent directly β instead, a complex process called the 4-way handshake is used to establish a secure connection.
WPA2 PROCESS: 1. Device discovers network 2. 4-way handshake (password verification) 3. Connection established
π Mini summary: WPA2 uses a shared password and a 4-way handshake to establish a secure connection.
Definition: The 4-way handshake is a sequence of 4 messages exchanged between a device and the access point to verify the password and establish a secure connection.
Why it matters: If we capture these 4 messages, we can crack the password offline.
THE 4-WAY HANDSHAKE: Message 1: AP β Device (ANonce) Message 2: Device β AP (SNonce) Message 3: AP β Device (GTK) Message 4: Device β AP (ACK)
π Mini summary: The 4-way handshake is the key to cracking WPA/WPA2 passwords.
Definition: Capturing the handshake means recording the 4-way handshake messages when a device connects to a network.
Why it matters: Without the handshake, we cannot crack the password.
School example: It's like recording the secret handshake so you can learn it later.
COMMAND TO CAPTURE HANDSHAKE: sudo airodump-ng -c [CH] --bssid [BSSID] -w capture wlan0mon (Look for "WPA Handshake" in the output)
π Mini summary: Use airodump-ng to capture the 4-way handshake.
Definition: A deauthentication attack disconnects a client from the network, forcing it to reconnect. When it reconnects, the handshake is sent again β and we can capture it.
Why it matters: If the network is quiet, we can use this attack to force a handshake.
Fun example: It's like turning off the Wi-Fi on your phone and turning it back on β the device has to reconnect.
COMMAND: sudo aireplay-ng -0 2 -a [BSSID] -c [Client MAC] wlan0mon (-0 = deauthentication attack) (2 = number of packets to send)
π Mini summary: Deauthentication forces a client to reconnect, giving us a handshake.
Definition: The PMKID (Pairwise Master Key Identifier) attack is a newer method that captures the PMKID from the access point, without needing a client to connect.
Why it matters: It works even if no clients are connected to the network.
COMMAND: sudo hcxdumptool -i wlan0mon --enable_status=1 -o capture.pcap sudo hcxpcaptool -z handshake.txt capture.pcap
π Mini summary: PMKID attack captures the PMKID from the AP directly.
Definition: A dictionary attack is a method of trying many passwords from a list (a dictionary) against the captured handshake.
Why it matters: This is the most common way to crack WPA/WPA2 passwords.
Simple explanation: It's like trying every key on a keyring to see which one opens the door.
COMMAND: sudo aircrack-ng -w dictionary.txt capture-01.cap (-w = wordlist/dictionary file)
π Mini summary: Dictionary attacks try many passwords from a list.
Definition: aircrack-ng can crack WPA/WPA2 handshakes using a dictionary.
Why it matters: This is the tool we use for offline password cracking.
COMMAND: sudo aircrack-ng -w /usr/share/wordlists/rockyou.txt capture-01.cap
π Mini summary: aircrack-ng uses a dictionary to crack WPA passwords.
Definition: hashcat is a more powerful password cracking tool that can use GPU acceleration for faster cracking.
Why it matters: hashcat is much faster than aircrack-ng for large dictionaries.
COMMAND: sudo hashcat -m 22000 handshake.txt /usr/share/wordlists/rockyou.txt (-m 22000 = WPA/WPA2 mode)
π Mini summary: hashcat is a faster, more powerful cracking tool.
Definition: A dictionary is a list of passwords to try. The quality of the dictionary affects the success rate.
Why it matters: A good dictionary has common passwords, phrases, and variations.
COMMON DICTIONARIES: - rockyou.txt (in Kali Linux) - SecLists (online) - Custom dictionaries (created for specific targets)
π Mini summary: A good dictionary is essential for successful cracking.
1. sudo airmon-ng start wlan0 β Enable monitor mode
2. sudo airodump-ng wlan0mon β Find target
3. sudo airodump-ng -c [CH] --bssid [BSSID] -w capture wlan0mon
β Capture on target
4. sudo aireplay-ng -0 2 -a [BSSID] -c [Client MAC] wlan0mon
β Deauth to force handshake (if needed)
5. Wait for "WPA Handshake" in airodump-ng
6. sudo aircrack-ng -w dictionary.txt capture-01.cap
β Crack the password
π Mini summary: The complete workflow: monitor β scan β capture β deauth (if needed) β crack.
hashcat can use your graphics card (GPU) to crack passwords much faster than a CPU.
COMMAND: sudo hashcat -m 22000 -a 0 handshake.txt rockyou.txt
π Mini summary: hashcat uses GPU for faster cracking.
Definition: You should only use these techniques on networks you own or have explicit permission to test.
Why it matters: Unauthorised access is illegal and unethical.
Nigerian example: Under the Cybercrime (Prohibition, Prevention, etc.) Act 2015, unauthorised access to networks is a crime. Always get permission.
π Mini summary: Only test networks you own or have permission to test.
Definition: A strong password is long and complex β it has a mix of uppercase, lowercase, numbers, and special characters.
Why it matters: Strong passwords are much harder to crack with a dictionary attack.
WEAK: password123 STRONG: MySecureP@ssw0rd2024!
π Mini summary: Strong passwords are essential for Wi-Fi security.
Definition: WPA3 is the newest Wi-Fi security standard. It is even stronger than WPA2 and is not vulnerable to the same attacks.
Why it matters: As WPA3 becomes more common, older attacks will no longer work.
π Mini summary: WPA3 is the future β stronger and more secure.
sudo airmon-ng start wlan0sudo airodump-ng wlan0monsudo airodump-ng -c [CH] --bssid [BSSID] -w capture wlan0monsudo aireplay-ng -0 2 -a [BSSID] -c [Client MAC] wlan0monsudo aircrack-ng -w rockyou.txt capture-01.capMONITOR β SCAN β CAPTURE β DEAUTH β WAIT β STOP β CRACK
Tip: Set up a lab with a WPA2 network. Walk through the capture and cracking process slowly. Emphasise the importance of the deauthentication attack and the dictionary file.
The PMKID attack was discovered in 2018. It allows cracking WPA/WPA2 networks without needing a client to be connected.
sudo β many tools need administrator privileges.
DEVICE ACCESS POINT
| |
| β Message 1 (ANonce) |
| β (AP sends nonce) |
| |
| β Message 2 (SNonce) |
| β (Device sends nonce) |
| |
| β Message 3 (GTK) |
| β (AP sends group key) |
| |
| β Message 4 (ACK) |
| β (Device acknowledges) |
| |
| Feature | WPA | WPA2 | WPA3 |
|---|---|---|---|
| Security | Medium | Strong | Strongest |
| Encryption | TKIP | AES | AES |
| Status | Legacy | Current | New |
+-------------------+
| airmon-ng start | β Enable monitor mode
+-------------------+
|
+-------------------+
| airodump-ng scan | β Find target
+-------------------+
|
+-------------------+
| airodump-ng -c | β Capture on target
+-------------------+
|
+-------------------+
| aireplay-ng -0 | β Deauth to force handshake
+-------------------+
|
+-------------------+
| Wait for handshake | β "WPA Handshake" in output
+-------------------+
|
+-------------------+
| aircrack-ng | β Crack with dictionary
+-------------------+
We included mini summaries after each lesson. Let's now wrap up the entire module.
In this module, we explored WPA/WPA2 security and how to crack it. We learned about the 4-way handshake, the deauthentication attack, and the PMKID attack. We used airodump-ng to capture the handshake, aireplay-ng to force a handshake with deauth, and aircrack-ng and hashcat to crack the password.
We also discussed the importance of strong passwords, ethical considerations, and the future of Wi-Fi security with WPA3. With this knowledge, you can now assess the security of WPA/WPA2 networks.
Match the term with its description:
| Term | Description |
|---|---|
| 1. WPA2 | A. Captures handshakes |
| 2. 4-way handshake | B. Disconnects clients |
| 3. Deauthentication | C. Cracks passwords |
| 4. airodump-ng | D. Strong Wi-Fi standard |
| 5. aircrack-ng | E. Password exchange |
Answers: 1-D, 2-E, 3-B, 4-A, 5-C
Scenario: You are testing a WPA2 network for a client. The network is active, but no clients are connected. You need to capture a handshake.
In groups, set up a WPA2 network in a lab. Practice the full workflow: capture handshake, deauth a client, and crack the password using a dictionary. Document your steps and share with the class.
Research the rockyou.txt dictionary. Write a short report on where it comes from, how many passwords it contains, and why it's commonly used.
Create a reference guide for WPA handshake capture and cracking. Include: commands, explanation of each step, and common troubleshooting tips.
Set up a WPA2 network in a lab. Capture the handshake and crack the password using a dictionary. Submit your capture file, the cracked password, and a report explaining each step.
Research and perform the PMKID attack using hcxdumptool and hcxpcaptool. Write a report comparing it to the traditional handshake capture method.
In Module 6, we will explore WPS Attacks and Weakness Exploitation. We'll learn about the Wi-Fi Protected Setup (WPS) protocol, its vulnerabilities, and how to exploit them using tools like reaver and bully.
See you in Module 6!
π€ End of Module 5 β WPA/WPA2 Handshake Capture and Cracking π
βThe shortcut that became a security backdoor.β
In Module 5, we learned how to capture and crack WPA/WPA2 handshakes. But what if there was an easier way? What if there was a shortcut that could give you access without needing to capture a handshake?
That shortcut is called WPS β Wi-Fi Protected Setup. WPS was designed to make it easy for people to connect devices to their Wi-Fi networks. Instead of typing a long password, you could press a button or enter a short PIN.
But this convenience came with a big problem. The PIN-based method is weak and can be cracked in a matter of hours. Attackers can brute-force the PIN and get the network password.
In this module, we will learn about WPS, why it's vulnerable, and how to exploit it using tools like reaver and bully. We'll also cover the pixie dust attack, which is even faster.
Let's find the shortcut! π
By the end of this module, you will be able to:
In a neighbourhood in Lagos, Nigeria, there was a house with a very convenient feature. The owner had left a spare key under the doormat. It was easy β anyone who needed to get in could just lift the mat and use the key.
But one day, a young boy named Tunde noticed the key. He didn't need to pick the lock or break a window β he just lifted the mat, took the key, and opened the door.
The owner thought the spare key was convenient, but it was also a security risk. Anyone who knew about it could get in.
WPS is like that key under the doormat. It was designed for convenience, but it creates a security backdoor. Attackers can use it to get into the network without needing to crack the main password.
Definition: WPS (Wi-Fi Protected Setup) is a feature on many routers that makes it easy to connect devices to the network without typing a password.
Why it matters: WPS can be a security risk because it can be exploited by attackers.
Simple explanation: WPS is like a shortcut β it lets you into the network without the main key. But shortcuts can be dangerous.
WPS = WI-FI PROTECTED SETUP (A shortcut for connecting devices)
π Mini summary: WPS is a convenience feature that can be a security risk.
There are two main ways WPS works:
Home example: It's like a garage door opener β you press a button and the door opens.
WPS METHODS: 1. Push Button (PBC) β Press and connect 2. PIN β Enter a short code
π Mini summary: WPS uses a push button or a PIN to connect devices.
Definition: The WPS PIN vulnerability is a design flaw that allows attackers to guess the PIN in a few hours.
Why it matters: The PIN is only 8 digits, and the router checks it in two halves. This makes it easy to brute-force.
Fun example: It's like a lock with only 10,000 possible combinations instead of 100 million.
WPS PIN: 8 digits (10^8 = 100 million combinations) But router checks in two halves β much easier to guess
π Mini summary: The WPS PIN is easy to guess because of a design flaw.
Definition: A brute-force attack on WPS involves trying every possible PIN until the correct one is found.
Why it matters: With the right tools, this can be done in a few hours.
PIN ATTACK: Try PIN 00000000 Try PIN 00000001 Try PIN 00000002 ... until 99999999
π Mini summary: Brute-force attacks try all possible PINs.
Definition: reaver is the most popular tool for brute-forcing WPS PINs.
Why it matters: It's simple to use and very effective.
COMMAND: sudo reaver -i wlan0mon -b [BSSID] -c [CH] -vv (-i interface, -b BSSID, -c channel, -vv verbose)
π Mini summary: reaver is the main tool for WPS PIN cracking.
Definition: bully is another tool for WPS attacks. It is sometimes faster and more reliable than reaver.
Why it matters: Some routers are better handled by bully.
COMMAND: sudo bully wlan0mon -b [BSSID] -c [CH] -v 2
π Mini summary: bully is a faster alternative to reaver.
Definition: The pixie dust attack is a much faster method that exploits a weakness in how some routers generate the WPS PIN.
Why it matters: It can crack the PIN in seconds instead of hours.
Nigerian example: A test in Lagos showed that many older routers are vulnerable to the pixie dust attack.
COMMAND: sudo reaver -i wlan0mon -b [BSSID] -K 1 (-K 1 enables pixie dust attack)
π Mini summary: Pixie dust cracks WPS PINs in seconds.
Definition: Many routers have lockout protection β after a few failed attempts, they lock the WPS feature for a while.
Why it matters: Lockout makes brute-force attacks slower. But some routers don't have it, or it can be bypassed.
LOCKOUT: After 3 failed attempts, lock for 5 minutes. Slow down attacks.
π Mini summary: Lockout protection tries to slow down brute-force attacks.
Definition: Some tools can bypass lockout by waiting for the lock to expire and continuing.
Why it matters: Even with lockout, an attacker can still crack the PIN β it just takes longer.
Bypass: Wait for lockout, then continue.
π Mini summary: Lockout can be bypassed by waiting.
1. sudo airmon-ng start wlan0 β Enable monitor mode
2. sudo airodump-ng wlan0mon β Find target with WPS
3. sudo reaver -i wlan0mon -b [BSSID] -c [CH] -vv
β Start brute-force
4. Wait for PIN to be found
5. Reaver shows the PIN and WPA password
π Mini summary: The workflow: monitor β scan β reaver β get PIN and password.
Definition: When you crack the WPS PIN, you can retrieve the WPA/WPA2 password.
Why it matters: This is why WPS is so dangerous β it reveals the main network password.
WPS PIN β WPA/WPA2 PASSWORD
π Mini summary: Cracking WPS gives you the WPA password.
Definition: You can see if a network has WPS enabled by using airodump-ng. Look for the WPS column.
airodump-ng wlan0mon Look for "WPS" in the display.
π Mini summary: airodump-ng shows which networks have WPS enabled.
Definition: The best protection is to disable WPS on your router.
Why it matters: If WPS is off, these attacks won't work.
Simple explanation: If you remove the spare key from under the doormat, no one can use it.
π Mini summary: Disable WPS to protect your network.
Definition: You should only use WPS attacks on networks you own or have explicit permission to test.
Why it matters: Unauthorised access is illegal and unethical.
Nigerian example: In Nigeria, unauthorised access to networks is a cybercrime. Always get written permission.
π Mini summary: Only test WPS on networks you own or have permission to test.
Definition: Many newer routers have disabled WPS by default or have fixed the vulnerabilities.
Why it matters: WPS attacks are becoming less effective as routers get updated.
π Mini summary: WPS is being phased out β many new routers don't have it.
sudo airmon-ng start wlan0sudo airodump-ng wlan0monsudo reaver -i wlan0mon -b [BSSID] -c [CH] -vvMONITOR β SCAN β REAVER β WAIT β GET PASSWORD
Tip: Set up a lab with a router that has WPS enabled. Walk through the reaver attack. Emphasise the importance of disabling WPS.
The pixie dust attack works because some routers use a weak random number generator to create the WPS PIN. This allows attackers to calculate the PIN in seconds.
sudo β reaver needs administrator privileges.
+-------------------+
| airmon-ng start | β Enable monitor mode
+-------------------+
|
+-------------------+
| airodump-ng scan | β Find target with WPS
+-------------------+
|
+-------------------+
| reaver -i -b | β Start brute-force
+-------------------+
|
+-------------------+
| Wait for PIN | β Hours or seconds (pixie dust)
+-------------------+
|
+-------------------+
| Get password | β The WPA key
+-------------------+
WPS PIN: 8 digits Example: 12345678 Checksum: Last digit is a checksum Effective combinations: ~11,000
| Tool | Speed | Features |
|---|---|---|
| reaver | Slow (hours) | Standard, widely used |
| bully | Faster | More reliable on some routers |
| reaver + pixie | Very fast (seconds) | Exploits weak PRNG |
We included mini summaries after each lesson. Let's now wrap up the entire module.
In this module, we explored WPS (Wi-Fi Protected Setup) and its vulnerabilities. We learned that WPS was designed for convenience but has serious security flaws. The PIN method is easy to brute-force, and tools like reaver and bully can crack it in hours β or seconds with the pixie dust attack.
We also covered lockout protection and how it can be bypassed. The best defence against WPS attacks is to disable WPS on your router. We also emphasised the importance of ethical and legal use of these tools.
Match the term with its description:
| Term | Description |
|---|---|
| 1. WPS | A. Tool for WPS cracking |
| 2. PIN | B. Fast WPS attack |
| 3. reaver | C. Convenience feature |
| 4. pixie dust | D. Locks after failed attempts |
| 5. lockout | E. 8-digit code |
Answers: 1-C, 2-E, 3-A, 4-B, 5-D
Scenario: You are testing a network for a client. You notice that WPS is enabled on their router.
In groups, set up a router with WPS enabled in a lab. Use reaver to perform a WPS attack. Document the process and share your results with the class.
Research the history of WPS vulnerabilities. Write a short report on how the pixie dust attack works and why it's so fast.
Create a poster explaining WPS security. Include: what WPS is, why it's vulnerable, how to test it, and how to protect against it. Make it suitable for a non-technical audience.
Set up a WPS-enabled router in a lab. Use reaver or bully to crack the PIN and retrieve the WPA password. Submit a report with your steps, commands, and results.
Research the WPS lockout feature on three different router models. Write a report on how they implement lockout and whether they are vulnerable to bypassing.
In Module 7, we will explore Advanced Attacks and Post-Exploitation. We'll learn about Evil Twin attacks, rogue access points, and how to intercept traffic after gaining access.
See you in Module 7!
π End of Module 6 β WPS Attacks and Weakness Exploitation π
βOnce you're inside, what do you do? And how do you get even more control?β
In the previous modules, we learned how to crack WEP, capture WPA handshakes, and exploit WPS. But what if we want to do more than just get the password? What if we want to intercept traffic, steal data, or even impersonate a network?
This is the world of advanced attacks and post-exploitation. Once you've gained access to a network, you can do much more than just browse the internet. You can listen in on conversations, redirect websites, and even create fake networks to trick users.
In this module, we will explore the Evil Twin attack, rogue access points, and Man-in-the-Middle (MITM) techniques. We'll also learn how to use tools like airbase-ng and ettercap to take control.
Let's become the puppeteer! π
By the end of this module, you will be able to:
In a busy market in Lagos, Nigeria, there was a shop that looked exactly like a popular electronics store. It had the same name, the same sign, and the same colours. But it was fake.
People entered thinking it was the real store. The fake shop had cameras that recorded everything customers did β what they looked at, what they bought, and even their credit card details.
After the customers left, the shop owner would use this information to steal their money or sell their data.
This is exactly what an Evil Twin attack is. You create a fake network that looks exactly like a real one. Users connect to it, and you capture all their traffic.
Definition: An Evil Twin attack is when an attacker creates a fake Wi-Fi network that looks exactly like a legitimate one. Users connect to it, thinking it's real.
Why it matters: Once connected, the attacker can intercept all the user's traffic β including passwords, emails, and messages.
Simple explanation: It's like a fake shop that looks exactly like a real one. You walk in thinking it's the real shop, but it's run by thieves.
EVIL TWIN = FAKE NETWORK (Looks real, but is controlled by the attacker)
π Mini summary: An Evil Twin is a fake network that tricks users into connecting.
Definition: airbase-ng is a tool that creates fake access points (rogue APs).
Why it matters: It's the primary tool for setting up Evil Twin attacks.
COMMAND: sudo airbase-ng -e "FreeWiFi" -c 6 wlan0mon (-e ESSID, -c channel)
π Mini summary: airbase-ng creates fake access points.
To set up an Evil Twin:
CREATE FAKE AP β FORWARD TRAFFIC β CAPTURE β DEAUTH REAL
π Mini summary: Evil Twin involves creating a fake AP and redirecting traffic.
Definition: A Man-in-the-Middle attack is when an attacker intercepts communications between two parties without them knowing.
Why it matters: The attacker can read, modify, or even block the communication.
Fun example: It's like a messenger who reads your letter, changes it, and then delivers it β and neither you nor the receiver knows.
USER β ATTACKER β SERVER (The attacker is in the middle)
π Mini summary: MITM attacks intercept and manipulate communications.
Definition: ettercap is a tool for Man-in-the-Middle attacks. It can capture traffic, inject packets, and more.
Why it matters: It's one of the most powerful MITM tools available.
COMMAND: sudo ettercap -T -M arp /target// /gateway// (-T text mode, -M arp for ARP spoofing)
π Mini summary: ettercap is a powerful MITM tool.
Definition: ARP spoofing is a technique that redirects traffic through the attacker's machine.
Why it matters: It's the most common way to perform MITM attacks on a local network.
ARP SPOOFING: Attacker sends fake ARP replies β Traffic goes to attacker
π Mini summary: ARP spoofing redirects traffic to the attacker.
Definition: DNS spoofing is when an attacker redirects a user to a fake website.
Why it matters: It can be used for phishing or stealing credentials.
DNS SPOOFING: User tries to go to bank.com β Goes to fake-bank.com
π Mini summary: DNS spoofing redirects users to fake websites.
Definition: SSL stripping is a technique that downgrades HTTPS to HTTP, making traffic readable.
Why it matters: It allows attackers to see sensitive data that should be encrypted.
Simple explanation: It's like taking a sealed envelope and opening it, reading it, and then resealing it.
π Mini summary: SSL stripping removes encryption from HTTPS traffic.
Definition: A rogue access point is an unauthorised Wi-Fi access point on a network.
Why it matters: It can be used to bypass security and capture traffic.
Nigerian example: In a busy office in Lagos, an attacker might plant a small device that acts as a rogue AP, hidden under a desk.
π Mini summary: A rogue AP is an unauthorised access point.
Definition: Post-exploitation is the phase after gaining access to a network. It involves expanding control, stealing data, and maintaining access.
Why it matters: Getting in is just the beginning β what you do next determines the impact.
POST-EXPLOITATION: 1. Capture traffic 2. Steal credentials 3. Move laterally 4. Maintain persistence
π Mini summary: Post-exploitation is what you do after gaining access.
Definition: Once you are in the middle, you can capture and analyse all traffic.
Why it matters: This is where you get valuable data like passwords and session tokens.
TOOLS: tcpdump, Wireshark, tshark
π Mini summary: Capture traffic to extract valuable data.
Definition: Credential theft is when an attacker steals usernames and passwords from captured traffic.
Why it matters: Credentials can be used for further attacks or sold.
CREDENTIAL THEFT: - HTTP Basic Auth - Form submissions - Session cookies
π Mini summary: Credential theft steals usernames and passwords.
Definition: Lateral movement is when an attacker moves from one machine to another within the network.
Why it matters: It allows the attacker to reach sensitive systems and data.
π Mini summary: Lateral movement spreads the attack within the network.
Definition: Maintaining access means keeping a way back in even if the initial entry is discovered.
Why it matters: It ensures the attacker can return later.
METHODS: - Backdoors - Persistent scripts - Scheduled tasks
π Mini summary: Maintain access to return later.
Definition: Defending against these attacks requires multiple layers of security.
Why it matters: No single defence is enough β you need a combination.
π Mini summary: Multiple layers of defence are needed against advanced attacks.
sudo airmon-ng start wlan0sudo airbase-ng -e "TargetSSID" -c 6 wlan0monsudo echo 1 > /proc/sys/net/ipv4/ip_forwardsudo aireplay-ng -0 0 -a [BSSID] wlan0monsudo tcpdump -i at0 -w capture.pcapMONITOR β CREATE FAKE AP β FORWARD β DEAUTH β CAPTURE
Tip: Use the counterfeit shop story to explain the Evil Twin concept. Emphasise the importance of using VPNs and verifying network names.
The Evil Twin attack gets its name from the idea of a "twin" β a copy that looks identical to the real thing, but is evil.
+-----------------------------------------------+ | USER connects to "FreeWiFi" (fake) | | | | | ATTACKER intercepts traffic | | | | | ATTACKER forwards to real internet | | | | | USER thinks they are on real internet | +-----------------------------------------------+
USER ATTACKER SERVER
| | |
| β Request β | |
| | β Request β |
| | |
| | β Response β |
| β Response β | |
| | |
| Phase | Action |
|---|---|
| 1. Capture | Collect traffic and data |
| 2. Steal | Extract credentials and sensitive info |
| 3. Move | Lateral movement within the network |
| 4. Persist | Maintain access |
We included mini summaries after each lesson. Let's now wrap up the entire module.
In this module, we explored advanced attacks and post-exploitation techniques. We learned about the Evil Twin attack β creating a fake network to trick users β and how to use airbase-ng to set it up. We covered Man-in-the-Middle (MITM) attacks, ARP spoofing, DNS spoofing, and SSL stripping, using tools like ettercap.
We also discussed post-exploitation β what to do after gaining access, including traffic capture, credential theft, lateral movement, and maintaining persistence. Finally, we covered defence strategies to protect against these advanced attacks.
Remember: with great power comes great responsibility. Only use these techniques in authorised environments.
Match the term with its description:
| Term | Description |
|---|---|
| 1. Evil Twin | A. Creates fake APs |
| 2. airbase-ng | B. Intercepts communications |
| 3. MITM | C. Fake network |
| 4. ARP spoofing | D. Redirects traffic |
| 5. ettercap | E. MITM tool |
Answers: 1-C, 2-A, 3-B, 4-D, 5-E
Scenario: You are testing the security of a hotel's Wi-Fi. You notice that many guests are using the network without a VPN.
In groups, design an Evil Twin attack demonstration for a lab environment. Include: setting up the fake AP, deauthing the real one, and capturing traffic. Present your design to the class.
Research a real-world case of an Evil Twin attack. Write a report on how it happened, what data was stolen, and how it could have been prevented.
Create a security awareness poster about Evil Twin attacks. Include: what they are, how to recognise them, and how to stay safe. Make it suitable for a non-technical audience.
In a lab environment, set up an Evil Twin attack using airbase-ng. Capture traffic from a test device. Write a report on your setup, steps, and findings.
Research and write a report on how to detect Evil Twin and rogue AP attacks. Include tools like WIDS (Wireless Intrusion Detection Systems) and best practices.
In Module 8, we will cover Defence, Mitigation, and Reporting. We'll learn how to protect networks from all the attacks we've studied, and how to write professional security assessment reports.
This is the final module β you're almost a Certified Aircrack-ng User!
See you in Module 8!
π End of Module 7 β Advanced Attacks and Post-Exploitation π
βHow to protect networks and tell the world what you found.β
Welcome to the final module of the Certified Aircrack-ng User course! π You've learned how to crack WEP, capture WPA handshakes, exploit WPS, and perform advanced attacks. But knowledge without responsibility is dangerous.
In this module, we will learn how to defend against all the attacks we've studied. We'll cover mitigation techniques β how to make networks secure. And we'll learn about reporting β how to professionally communicate your findings to clients or management.
Being a good security professional is not just about breaking things β it's about fixing them and helping others stay safe.
Let's become defenders! π‘οΈ
By the end of this module, you will be able to:
In a large company in Lagos, Nigeria, there was a security consultant named Chioma. Chioma was hired to test the company's Wi-Fi security. She used the tools we've learned β cracking WEP, capturing handshakes, and even performing an Evil Twin attack.
But Chioma didn't just break things and leave. After her tests, she wrote a detailed report for the company. She explained:
Because of Chioma's report, the company made changes β they upgraded to WPA3, disabled WPS, and trained their staff on security. Chioma had helped them become more secure.
This is what a true security professional does. Not just breaking, but building.
Definition: Defence in depth is a strategy that uses multiple layers of security. If one layer fails, others are there to protect.
Why it matters: No single security measure is perfect. Using many layers makes it much harder for attackers.
Simple explanation: It's like having a locked gate, a guard dog, and an alarm system. If one fails, you still have others.
DEFENCE IN DEPTH: LAYER 1: Strong encryption (WPA2/WPA3) LAYER 2: Disable WPS LAYER 3: Strong passwords LAYER 4: Monitoring and detection LAYER 5: User education
π Mini summary: Use multiple layers of security for better protection.
Definition: WPA2 and WPA3 are the strongest Wi-Fi encryption standards available.
Why it matters: They protect your data from being easily intercepted and decrypted.
Home example: Using WPA2 on your home router is like having a strong lock on your front door.
WPA2: Strong, widely supported WPA3: Stronger, newer
π Mini summary: Always use WPA2 or WPA3 for your Wi-Fi networks.
Definition: 802.11w is a standard that protects management frames (like deauthentication frames) from being forged.
Why it matters: It prevents deauthentication attacks and other management frame exploits.
Simple explanation: It's like adding a seal to official documents so they can't be faked.
802.11w = PROTECTED MANAGEMENT FRAMES (Stops deauth attacks)
π Mini summary: 802.11w protects against management frame attacks.
Definition: Disabling WPS removes the easiest entry point for attackers.
Why it matters: WPS attacks are very effective. Turning off WPS stops them.
Nigerian example: A bank in Lagos disabled WPS on all their routers after a security assessment revealed the vulnerability.
WPS OFF = WPS ATTACKS WON'T WORK
π Mini summary: Disable WPS to close a major security hole.
Definition: A strong password is long, complex, and unique. It should include uppercase, lowercase, numbers, and special characters.
Why it matters: Weak passwords are easy to crack with dictionary attacks.
WEAK: password123 STRONG: MySecureP@ssw0rd2024!
π Mini summary: Use strong, unique passwords for all networks.
Definition: Firmware updates fix security vulnerabilities in routers and access points.
Why it matters: Many attacks exploit known vulnerabilities that have been patched in newer firmware.
Simple explanation: It's like getting a vaccine β it protects you from new threats.
π Mini summary: Keep your router firmware updated.
Definition: Monitoring means watching your network for suspicious activity.
Why it matters: Early detection can stop attacks before they succeed.
MONITORING TOOLS: - WIDS (Wireless Intrusion Detection Systems) - WIPS (Wireless Intrusion Prevention Systems) - Log analysis
π Mini summary: Monitor your network to detect attacks early.
Definition: Rogue AP detection is the process of finding unauthorised access points on your network.
Why it matters: Rogue APs are a common way for attackers to bypass security.
DETECTION METHODS: - Scanning for unknown BSSIDs - Checking for SSID spoofing - Using WIDS tools
π Mini summary: Find rogue APs to prevent unauthorized access.
Definition: User education is training people to recognise and avoid security threats.
Why it matters: Many attacks rely on human error β educated users are less likely to fall for them.
School example: Teaching students not to click on suspicious links is like teaching them to look both ways before crossing the street.
π Mini summary: Educate users to strengthen your security.
Definition: Ethical hackers use their skills to improve security, not to cause harm.
Why it matters: With great power comes great responsibility. You must act ethically and legally.
ETHICAL RESPONSIBILITIES: 1. Get permission before testing. 2. Protect sensitive data. 3. Report findings responsibly. 4. Help fix the issues.
π Mini summary: Use your skills to help, not harm.
Definition: A security assessment report is a document that summarises your findings and recommendations.
Why it matters: It communicates your results to clients or management so they can take action.
REPORT STRUCTURE: 1. Executive Summary 2. Methodology 3. Findings (with evidence) 4. Risk Assessment 5. Recommendations 6. Conclusion
π Mini summary: A good report explains what you found and how to fix it.
Definition: Risk assessment is the process of evaluating how serious each vulnerability is.
Why it matters: You can't fix everything at once β you need to prioritise.
RISK LEVELS: - High (critical) - Medium (important) - Low (minor)
π Mini summary: Prioritise fixing the most serious vulnerabilities first.
Definition: Incident response is the process of responding to a security breach.
Why it matters: A quick and effective response can minimise damage.
INCIDENT RESPONSE STEPS: 1. Detect 2. Contain 3. Eradicate 4. Recover 5. Learn
π Mini summary: Have a plan for responding to attacks.
Definition: Compliance means following the laws and regulations that apply to your work.
Why it matters: Non-compliance can result in fines and legal action.
Nigerian example: The Cybercrime (Prohibition, Prevention, etc.) Act 2015 sets rules for cybersecurity in Nigeria. Always operate within the law.
π Mini summary: Know and follow the laws that apply to your work.
Definition: A security professional is always learning and adapting to new threats.
Why it matters: The cybersecurity landscape changes constantly β you must keep up.
CONTINUOUS LEARNING: - Stay updated on new attacks. - Learn new tools and techniques. - Share knowledge with others.
π Mini summary: Keep learning to stay effective.
PLAN β RECON β TEST β ANALYSE β REPORT β REVIEW
Tip: Have students write a sample security assessment report for a fictional company. This reinforces the importance of communication in security work.
The OWASP Top 10 is a list of the most critical security risks for web applications. While it's not specific to Wi-Fi, it shows how security professionals think about prioritising risks.
+-----------------------------------+ | LAYER 5: User Education | +-----------------------------------+ | LAYER 4: Monitoring & Detection | +-----------------------------------+ | LAYER 3: Strong Passwords | +-----------------------------------+ | LAYER 2: WPA2/WPA3 Encryption | +-----------------------------------+ | LAYER 1: Disable WPS | +-----------------------------------+
| Section | Content |
|---|---|
| Executive Summary | Overview of findings |
| Methodology | How the test was done |
| Findings | Detailed vulnerabilities |
| Risk Assessment | Priority of each finding |
| Recommendations | How to fix each issue |
| Conclusion | Final thoughts |
+-------------------+-------------------+-------------------+ | Standard | Security | Status | +-------------------+-------------------+-------------------+ | WEP | Very weak | Obsolete | | WPA | Weak | Legacy | | WPA2 | Strong | Current | | WPA3 | Strongest | New | +-------------------+-------------------+-------------------+
We included mini summaries after each lesson. Let's now wrap up the entire course.
In this final module, we learned how to defend against the attacks we've studied throughout the course. We covered defence in depth β using multiple layers of security β and the importance of strong encryption (WPA2/WPA3), disabling WPS, and using strong passwords.
We also learned about monitoring, rogue AP detection, and user education. We discussed the ethical responsibilities of a security professional, how to write a professional security assessment report, and how to prioritise risks.
Finally, we covered incident response, legal compliance, and the importance of continuous learning. You are now equipped not just to break, but to build and protect.
You are now a Certified Aircrack-ng User! π
Match the term with its description:
| Term | Description |
|---|---|
| 1. Defence in depth | A. Latest Wi-Fi standard |
| 2. WPA3 | B. Multiple security layers |
| 3. 802.11w | C. Responding to breaches |
| 4. Rogue AP | D. Management frame protection |
| 5. Incident response | E. Unauthorised access point |
Answers: 1-B, 2-A, 3-D, 4-E, 5-C
Scenario: You are hired to assess the security of a small business. You find that they use WEP, have WPS enabled, and use a weak password.
In groups, create a security awareness poster for a public Wi-Fi environment. Include: risks, tips for safe usage, and what to do if they suspect a problem.
Write a sample security assessment report for a fictional company. Include: executive summary, methodology, findings, risk assessment, and recommendations.
Create a Wi-Fi security checklist for home users. Include: encryption, WPS, passwords, firmware updates, and user education. Make it practical and easy to follow.
Conduct a security assessment of your own home Wi-Fi network. Write a report on your findings and implement the necessary fixes.
Research and write a report on a recent Wi-Fi security vulnerability (like Kr00k or the WPA2 Key Reinstallation Attack). Explain the vulnerability, its impact, and how to mitigate it.
You have completed the Certified Aircrack-ng User course! π
You now have a deep understanding of Wi-Fi security β from the fundamentals to advanced attacks and defence. You can:
Here are some next steps to continue your journey:
You have the power to make the digital world safer. Use it wisely! ππ‘οΈ
π‘οΈ End of Module 8 β Defence, Mitigation, and Reporting π
πππ Congratulations on completing the course! You are now a Certified Aircrack-ng User! πππ